Weaknesses of type CWE-209

429 results

Exposição de Informações Sensíveis em Mensagens de Erro

A aplicação retorna mensagens de erro que revelam detalhes internos do sistema — como caminhos de arquivo, nomes de banco de dados, versões de software ou stack traces — para usuários não autorizados. Um atacante usa essas informações para mapear a infraestrutura e planejar exploits direcionados.

Example

Um formulário de login mostra 'Erro SQL: usuário não encontrado em tabela users_prod' ao invés de 'Credenciais inválidas'. O atacante descobre o nome exato da tabela e começa testes de SQL injection. Ou um erro de exceção expõe '/var/www/html/config.php:42', revelando a estrutura do servidor.

How to mitigate

Exiba mensagens de erro genéricas ao usuário final ('Operação não permitida'), e registre os detalhes técnicos apenas em logs internos do servidor. Desabilite stack traces e debug info em produção, use tratamento centralizado de exceções e valide/sanitize todo output antes de devolvê-lo ao cliente.

CVE-2026-45728HIGHAlgernon: Single-file mode unconditionally enables debug modeEPSS 0.3%CVE-2023-38010MEDIUMMultiple Vulnerabilities in IBM Cloud Pak SystemEPSS 0.3%CVE-2025-13978MEDIUMGeneration of Error Message Containing Sensitive Information in GitLabEPSS 0.3%CVE-2024-51460MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.3%CVE-2026-78693MEDIUMIncomplete redaction re-attaches the original error path in AshGraphql, leaking internal field namesEPSS 0.3%CVE-2025-25045MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.3%CVE-2026-59943MEDIUMDompdf: Embedded SVG images can leak existence of files and directories within the filesystemEPSS 0.3%CVE-2023-40457—The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause aEPSS 0.3%CVE-2023-38281MEDIUMMultiple Vulnerabilities in IBM Cloud Pak SystemEPSS 0.3%CVE-2020-2505LOWSensitive information via generation of error messages vulnerability in QESEPSS 0.3%CVE-2026-54561MEDIUMMCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_import via unvalidated filePathEPSS 0.3%CVE-2025-66549LOWNextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directoryEPSS 0.3%CVE-2023-38017MEDIUMMultiple Vulnerabilities in IBM Cloud Pak SystemEPSS 0.3%CVE-2024-11625HIGHInformation Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from EPSS 0.3%CVE-2026-1030MEDIUMMultiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration AgentEPSS 0.3%CVE-2025-0279MEDIUMHCL Traveler is affected by generation of error messages containing sensitive informationEPSS 0.3%CVE-2026-11904MEDIUMSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2024-37162MEDIUMzsa Generates Error Messages Containing Sensitive InformationEPSS 0.3%CVE-2026-47248MEDIUMParse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callersEPSS 0.3%CVE-2024-37524MEDIUMIBM Analytics Content Hub information disclosureEPSS 0.3%